Network Security and Compliance Flashcards
7 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security and Compliance flashcards as text
You need to allow Azure Monitor to collect diagnostic logs from resources in a private VNet without public internet exposure. What should you configure?
Answer: Deploy Private Endpoints for Azure Monitor (Azure Monitor Private Link Scope)
Azure Monitor Private Link Scope (AMPLS) uses Private Endpoints to allow diagnostic data collection from VNet resources without traversing the public internet.
Which Azure Firewall rule collection type should be used to allow an on-premises server to initiate RDP sessions to Azure VMs?
Answer: Network rule collection
Network rule collections handle Layer 4 traffic (TCP/UDP/ICMP) based on source/destination IP and port, which is appropriate for allowing RDP on port 3389.
A security audit requires that all Azure resources have no public IP addresses. Which Azure Policy effect enforces this during resource deployment?
Answer: Deny
The Deny effect prevents deployment of resources that violate the policy condition, such as having a public IP address assigned.
You are designing a zero-trust network for Azure. Which combination of services best enforces micro-segmentation between application tiers?
Answer: NSGs on each subnet combined with Azure Firewall for inter-tier inspection
NSGs on each subnet enforce micro-segmentation at the subnet level, while Azure Firewall provides stateful deep inspection for traffic crossing tier boundaries.
Which feature in Azure Firewall allows it to identify and control traffic based on web categories such as gambling or social media?
Answer: Web Categories filtering
Azure Firewall Premium's Web Categories feature classifies URLs into categories (e.g., gambling, social media) and allows you to allow or deny entire categories.
An application deployed behind Azure Application Gateway WAF is returning 403 errors only for requests containing special characters in query strings. What is the most likely cause?
Answer: A WAF rule matching the special characters as a SQL injection or XSS pattern
WAF OWASP rules detect patterns like SQL injection and XSS, which can match special characters in query strings and generate 403 block responses.
You need to ensure that Azure Virtual Desktop session hosts can only be accessed through Azure Bastion and never via direct RDP from the internet. What is the correct approach?
Answer: Block port 3389 inbound in the subnet NSG and deploy Azure Bastion in the same VNet
Blocking port 3389 inbound at the NSG level prevents direct internet RDP, while Azure Bastion provides browser-based RDP/SSH access through TLS 443 without exposing port 3389.